Sign inSign up
Langfuse

dhi.io/langfuse

Langfuse 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.95, 2.95-debian, 2.95-debian13, 2.95.12, 2.95.12-debian, 2.95.12-debian13

Index digest:

sha256:7e70b0d1942e93230d29acadce4e47045285583e4efbf6b747188ed744fb7390

Manifest digest:

sha256:e5eef806dd85fe777c36882e147c973d991a0b0ac88838983e90be48eabe559f

Size

96.73 MB

Last pushed

14 hours ago

Vulnerabilities

2
15
17
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/langfuse:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/langfuse:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/langfuse@sha256:532ecb336867734c19aff255f7303fc3f97098f3ce131858ec8314c7667e2dd2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/langfuse@sha256:f3c93f0cdb53c0860513b70e4188c5ced18ab4e1c0ec9720da9447952e36ca18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/langfuse@sha256:8d82311e3677694b0f9ca63af56232db861b4b5b8c715567e4a9147143118ccb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/langfuse@sha256:fe1ad86b3956318272b92330adb046adf4001baf0948627389f2e004dd1aa0ee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/langfuse@sha256:d5b60017f070e55ada7f9b649f6c0801e26a7f9c8e3093b61140b3c159e039cd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/langfuse@sha256:30780fe854fdf1c5bb2bfa6d69f4e2a83c16cc99767a9fc9fca492d11c775dd6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/langfuse@sha256:87a915f228cb413282aaf4cb6902eebdb144e42b3c2a5fb3e97b8923bfb2bf7a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/langfuse@sha256:ec2f4bab2c06aad877fd91f1ca25fdd82457a8d748a642b07699e6e485368738
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/langfuse@sha256:57db7f9d959115cdca4bb0b11a2250fd87fd62132b3fa7d44a86b1f63992cc83
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/langfuse@sha256:423b39024a9c07239f7bfa7c92625de2fc8f8aa5f211234aaa40015096169f9b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/langfuse@sha256:4663db7d850cdd3e4de61b5d1904c8f4a0aa87dcdcb145e61c3500c08f4f6ff5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/langfuse@sha256:d214b14769c2d7e82a15e803a4a243ad791f4b4b067f816f0766792e604b63c9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/langfuse@sha256:94b2d2da84c788746c53e92492779541bff08d95b4f263c479efbe7862bfbbca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/langfuse@sha256:ccc742ffe37154de0cb43dde9c1f3e7ce87cefe9ed630d619db1ae2a90f962cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/langfuse@sha256:63f575e9c619a8b354b56feefd3087ca2167839bdc4010c161cc6dca31424617